I built a new inbound ports display https://gw.ampr.org/router/ports.svg which shows a significant amount of traffic that SANS and others identify as being aimed at vulnerable ports on various pieces of equipment.
I don't want to just block them, as they have legitimate uses, but if you're running your own firewall, you might want to block them yourself if you don't have any need for the legitimate use. - Brian